Privacy policy
- Data Controller
The data controller is:
Herbarium Adriaticum d.o.o.
Brest 14, 52420 Buzet
OIB: 25917063014
Email: info@herbariumadriaticum.com
- What data do we collect
We collect the following personal data:
- first and last name
- delivery address
- email address
- telephone number
- data required for invoicing
- order data
Card information is not stored on the Platform.
- Legal basis for processing
Personal data is processed on the basis of:
- performance of the contract (order fulfillment)
- compliance with legal obligations (accounting, tax regulations)
- legitimate interest (system security, prevention of abuse)
- consent (newsletter and marketing activities, if applicable)
- Purpose of processing
Data is processed for the following purposes:
- fulfillment of orders
- organization of delivery
- issuance of invoices
- communication with customers
- compliance with legal obligations
- protection of system security
- Data Sharing
Data can be forwarded:
- vendors for order execution
- delivery services
- payment partner (Monri Payments d.o.o.)
- accounting services
- IT hosting service providers
Data is not sold to third parties.
- Data retention period
Data is kept as long as necessary to fulfill contractual and legal obligations.
Accounting data are stored in accordance with the law (at least 11 years).
- User rights
The user has the right to:
- access to data
- correction of inaccurate data
- deletion of data
- restriction of processing
- data portability
- objection to processing
- filing a complaint with the Personal Data Protection Agency (AZOP)
The request is submitted via email.
- Data security
The platform uses SSL encryption and applies technical and organizational protection measures in accordance with GDPR regulations.
Card data is processed through a certified system in accordance with PCI DSS security standards.




